SU

Associate Information Security Officer

Stanford UniversityUnited StatesPosted Jul 23, 2026
Security AnalystRemoteMid
Job description

At Stanford, we are committed to creating meaning, solving complex challenges, and enriching lives on a global scale. We are seeking a talented Associate Information Security Officer to play a vital role in our dynamic team within the Information Security Office. In this position, you will support a broad range of information security activities, helping protect the university's digital resources and contributing to a culture of security awareness and accountability. 

The Information Security Office is a high-profile team with university-wide purview. We operate with a high degree of autonomy, and we expect each contributor to bring their own strengths to the tough challenges facing the university. 

The Cybersecurity Governance, Risk, and Compliance (GRC) team within the Information Security Office has an entrepreneurial spirit, and we invite you to help us grow while advancing your own career. 

In this role, you will support core GRC functions including security awareness and training, data risk assessments, add-in and plug-in reviews, and compliance support across applicable regulatory frameworks. A working knowledge of HIPAA is important, as the university handles protected health information across research, clinical, and administrative environments. 

You will report directly to the Senior Information Security Officer and work closely with team members across ISO and university departments to support the university's information security program. 

Typical Activities 

  • Perform add-in and plug-in reviews for university-sanctioned software and productivity tools, evaluating data access permissions, privacy risk, and alignment with university security standards.
  • Assist in maintaining compliance programs across applicable regulatory frameworks, including PCI DSS, HIPAA, GLBA, and other requirements as they apply to the university.
  • Manage the team's help ticket queue, triage requests, and independently resolve tickets within scope. 
  • Manage the universityʼs Minimum Security Standards compliance exception process, including reviewing exception requests for endpoints, servers, and applications, evaluating compensating controls, and coordinating approvals with appropriate stakeholders. 
  • Assist in developing and delivering the university-wide security awareness and training program, including phishing simulations, campaigns, and LMS administration. Track participation and measure effectiveness through assessment results. 
  • Support the universityʼs AI governance program by assisting in conducting security assessments of AI tools, platforms, and add-ins. Evaluate data access, privacy risk, and alignment with university AI governance standards, and prepare assessment reports with clear findings and recommendations. 
  • Conduct Data Risk Assessments (DRAs) for university systems, applications, and vendors handling sensitive or regulated data. Prepare risk reports with clear mitigation recommendations. 
  • Assist in drafting, reviewing, and maintaining information security policies, standards, and procedures in alignment with HIPAA, FERPA, GLBA, PCI DSS, and other applicable requirements. 
  • Support compliance activities including evidence gathering, control documentation, and coordination with internal and external assessors. 
  • Collaborate with cross-functional teams including IT, Legal, Finance, and HR to integrate security into broader university operations. 
  • Keep current on emerging threats, regulatory changes, and industry best practices to inform team activities. 
  • Perform other related duties assigned to support the information security program. 

 

Approved budgeted salary for this position is: $104,623-$135,000

 

REMOTE WORK: This position is eligible for permanently remote work, but keep the following in mind: our team operates on Pacific Time, and we adjust salary based on regions of the country. You may be expected to come to campus, but generally expect that to be no more than a few days each quarter. Weʼll pay for your travel if youʼre outside the greater Bay Area. See our admin guide for more information. https://adminguide.stanford.edu/chapters/human-resources/staff-employment-policies/remote-work-arrangements. 

 

Core Duties:

  • Develop procedures to safeguard computer configurations against accidental or unauthorized modification, destruction, or disclosure and to meet the data standards. 

  • Perform system security reviews and tests and write formal reports and follow up advisory memos. 

  • Receive reports on security breaches and risks, take appropriate action, and recommend solutions to minimize harm and liability. 

  • Monitor process and inspect system and network data for computer and network usage policy compliance, system integrity, and incident response. Interface with Information Security Office to report incidents. 

  • Participate in the development and documentation of information security standards, best practices and guidelines by drafting policies, standards and procedures. Deliver educational information and develop awareness for  system administrators and user community. 

  • Provide guidance in the design of secure system and network architectures.  

  • Evaluate new applications to comply with enterprise security standard.  Recommend and implement solutions identified through organizational security audits.  

  • Network with information security members from other communities. 

  • Translate technical information to users of various knowledge levels at outreach events such as presentations and meetings.

Minimum Education and Experience:

Bachelor’s degree plus three years relevant experience, or a combination of education and relevant experience.

Knowledge, Skills and Abilities:

  • Demonstrated knowledge and understanding of IT security trends and emerging technologies and an ability to relate them to Stanford and its objectives.

  • Thorough and demonstrated knowledge of networking protocols, principles, and intrusion detection devices, including firewalls and VPNs.

  • Fundamental architecture and configuration knowledge of desktop server and operating systems.

  • Solid understanding of security issues, techniques, and solutions.

  • Strong experience with debugging, troubleshooting, forensics and security utilities.

  • Basic understanding of scripting language.

  • In-depth knowledge of authentication protocols, encryption and other fundamental security technologies.

  • Excellent written and verbal communication skills.

  • High level of integrity and excellence judgment concerning proprietary and privacy issues.

View original posting on Oraclecloud